noeljackson/Supplychain Scan

Fail-closed dependency and repository supply-chain scan without executing project code

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathRepository path to scanno.
policyauto or strictnostrict
minimum-release-age-daysMinimum npm package publication age for Bun lockfilesno7
baselineReviewed Bun baseline path relative to the repositoryno.supplychain/bun-baseline.json
gitleaks-configExplicit reviewed Gitleaks config path inside the scan targetno""
scan-sourceRun repository, dependency, OSV, Bun, Gitleaks, and zizmor checksnotrue
imageOptional local or registry OCI image to inventory and scanno""
fail-on-severityMinimum Grype severity that fails an image scannohigh
only-fixedOnly fail image vulnerabilities for which a fix existsnofalse
vexExplicit reviewed OpenVEX document inside the checked-out repositoryno""
namedescription
sbomPath to the generated SPDX JSON SBOM when image is set